ZeroHour

CVE-2024-4182

CVSS 3.1
4.3 medium
EPSS
<1%p44
Published
()
Modified
Description

Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.

Vendors
mattermost
Products
mattermost server
Weakness
CWE-754
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.